From 2efadcca074d4110c82728715d17b1e3af8edf87 Mon Sep 17 00:00:00 2001 From: Satoshi Qazi Muhammed Date: Sun, 19 Jul 2026 00:11:53 -0700 Subject: [PATCH] fix: exclude public account-id fields from the private-key heuristic The hardcoded-secret scan flags any 64-hex 0x value in JSON as a possible private key. The restored balance-test fixtures store public 32-byte account IDs under "account" fields - public data by definition, tripping the scan as a false positive. Scope the exclusion to the exact field name rather than loosening the pattern itself. --- .github/workflows/security.yml | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/.github/workflows/security.yml b/.github/workflows/security.yml index d15ace6..00fa808 100644 --- a/.github/workflows/security.yml +++ b/.github/workflows/security.yml @@ -60,7 +60,8 @@ jobs: FOUND=0 echo "Checking for private keys in config files..." - if grep -rn --include="*.json" --include="*.py" -E "(0x[a-fA-F0-9]{64}|-----BEGIN.*PRIVATE)" . | grep -v node_modules | grep -v "chainId\|genesisHash\|parentId\|currencyIdScale\|typeAlias\|signedExtensions"; then + # "account" fields hold public 32-byte account IDs (balance-test fixtures), not private keys + if grep -rn --include="*.json" --include="*.py" -E "(0x[a-fA-F0-9]{64}|-----BEGIN.*PRIVATE)" . | grep -v node_modules | grep -v "chainId\|genesisHash\|parentId\|currencyIdScale\|typeAlias\|signedExtensions\|\"account\":"; then echo "::error::Possible private key found" FOUND=1 fi